Note di rilascio di Django 1.9.8¶
18 Luglio 2016
Django 1.9.8 risolve un problema di sicurezza e alcuni bug in 1.9.7.
18 Luglio 2016
Django 1.9.8 risolve un problema di sicurezza e alcuni bug in 1.9.7.
Unsafe usage of JavaScript’s Element.innerHTML could result in XSS in the
admin’s add/change related popup. Element.textContent is now used to
prevent execution of the data.
The debug view also used innerHTML. Although a security issue wasn’t
identified there, out of an abundance of caution it’s also updated to use
textContent.
Offline (Django 6.1):
HTML |
PDF |
ePub
Fornito da Read the Docs .